Blueprints
June 13

Evading the exorbitant expenses of endpoints

The cost of Virtual Private Cloud (VPC) endpoints has been eye-popping since its release in 2017. This talk will explain the architectural decisions of endpoints' implementation on a cloud platform while avoiding the wrath of the finance team.

In an enterprise space, especially in regulated organizations, there is an affinity to AWS VPC endpoints. It precludes the requirement of an egress path when connecting to AWS public endpoints because the traffic uses an AWS backbone.

The salient trade-off is a cost that becomes increasingly prominent as more and more AWS accounts are vended. This is a fundamental issue with the flat hourly price dimension that becomes runaway in the absence of oversight.

The way to curtail this cost is to deploy VPC endpoints as a shared service in a centralized hub-spoke model.

The key takeaways of this talk are:

  1. Architectural design of centralized endpoints
  2. DNS resolution of endpoints hosted in hub account from spoke accounts
  3. VPC layout design of hub account and its treatment as a core shared services account
Atif Siddiqui
Sr. Principal Cloud Architect, Silicon Valley Bank
Atif Siddiqui

Register for PlatformCon 2025

Connect with fellow platform practitioners, learn from the best in the industry and engage directly with speakers on Slack.
Community
Join over 20k platform engineers from all over the world
Slack
Share best practices, discuss new trends and tooling with 20k+ platform practitioners
Speakers
Engage with 200+ speakers in dedicated channels or directly in DMs